Privacy policy

Information on the processing of personal data under Regulation (EU) 2016/679.

Last updated: 2026-09-18

This English version is a courtesy translation of the Italian text, which is the only authoritative version and prevails in case of discrepancy.

Version 1.0 — English courtesy translation, 18 September 2026

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018 ("Privacy Code")


This notice is the single document by which LX20 Law Firm S.T.A. S.r.l. describes the processing of personal data carried out within the lx20lawfirm.com website, freely accessible services, the Personal Area, the Client Area, and the newsletter service. The document is divided into a General Part, applicable to all data subjects, and two Special Parts — A (Client Portal) and B (Newsletter) — which supplement the General Part and specifically govern the processing activities proper to each context. In the event of an apparent conflict, the more specific and protective provision for the data subject shall prevail.


Definitions used in this privacy policy

"Personal Data": any identified or identifiable information, including indirectly, relating to an individual, including a personal identification number, general identification data, or Personal Data that allow for direct identification (e.g., name, VAT number, address, email address, phone number, etc.) – see Art. 4(1)(1) GDPR.

"Processing": any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

"Data Controller": the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

"Data Processor": a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the controller.

"Data Subject": an identified or identifiable natural person. In this notice, the term refers to You.

"Navigation Data": the computer systems and software procedures used to operate this Platform acquire, during their normal operation, some Personal Data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects, but which by its very nature could — through processing and association with data held by third parties — allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users who connect to the Platform, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the operating system and the user's IT environment. This data is used for the sole purpose of obtaining anonymous statistical information on the use of the Platform and to check its correct functioning and is deleted immediately after processing.

"System Logs": for operation and maintenance purposes, this Platform and any third-party services it uses may collect system logs, which are files that record interactions and may also contain Personal Data, such as the IP address.


General Part

1. Data Controller

The Data Controller is LX20 Law Firm S.T.A. S.r.l., a limited liability company among lawyers, with registered office in Via San Raffaele 1, 20121 Milan (MI), Italy, Tax Code and VAT No. 14389480964, enrolled in the Companies' Register of Milan Monza Brianza Lodi under no. 14389480964, R.E.A. MI-2779437, share capital € 5,000.00 fully paid-up, enrolled in the special Register of Companies among Lawyers established at the Milan Bar Association pursuant to Art. 4-bis of Law No. 247 of 31 December 2012, in the person of its legal representative *pro tempore* (hereinafter "LX20", "Firm" or "Controller").

The Firm operates through its registered office in Milan and offices in Turin and New York (United States of America), which are attributable to the same Italian legal entity.

Controller's contact details for the purposes of this document:


2. Types of data processed

LX20 processes the following categories of personal data relating to natural persons with whom it comes into contact through the lx20lawfirm.com website and related services:

(a) Personal and contact data: name, surname, company name (if a legal entity), tax code, VAT number, postal address, email address, telephone numbers, professional role, place of work.

(b) Navigation data: IP address (in anonymised or pseudonymised form, where possible), browser and operating system type and version, pages visited, date and time of visit, referrer, session duration. This data is collected for IT security purposes and for aggregated statistical analysis of website usage.

(c) Data provided through contact, registration, and other forms: content of messages sent, any attached files, preferences regarding marketing communications, content of responses provided to self-service tools that may be available in the Personal Area.

(d) Personal Area access credentials: email address, password (stored in irreversibly encrypted form using cryptographic hash functions), session tokens, access logs. Any OAuth credentials from third-party providers (e.g., Google) are managed as described in §3.6.

(e) Two-factor authentication (2FA) data: TOTP secret key (encrypted at-rest), any backup codes generated upon registration, access timestamps.

(f) Professional and engagement-related data (for Firm Clients only): identification and contact data of the Client and their representatives, data relating to the assigned matter, technical and legal documentation provided or produced in connection with the engagement, any data of third parties necessary for the proper performance of the professional assignment (counterparties, authorities, external consultants). Such data is processed in accordance with the specific provisions set out in Special Part A.

(g) Data relating to anti-money laundering (AML/CDD) obligations: customer due diligence data pursuant to Legislative Decree no. 231 of 21 November 2007 and subsequent amendments, including identity documents, information on beneficial ownership, purpose and nature of the professional service, and source of funds. Such data is processed exclusively for the purposes of complying with statutory obligations.

(h) Consent-related data: record of the version of the Terms and Conditions and Privacy Policy accepted, timestamp of acceptance, marketing opt-ins/outs, log of requests to exercise rights, subsequent changes to consents given.

Special categories of data (Art. 9 GDPR): LX20 does not systematically collect data relating to health, political opinions, religious or trade union beliefs, sexual orientation, or ethnic origin through the website or the Personal Area. Should such data emerge in the context of a specific professional engagement (e.g., a labour law dispute), the processing is limited to the purposes of the engagement and is covered by the specific provisions of Special Part A.


3. Purposes of processing and legal basis

The data indicated above are processed for the following purposes, each based on its respective legal basis:

3.1 Provision of the website and public services

To allow the user to consult the website's content, download public materials, and use freely accessible services. Legal basis: Art. 6(1)(b) GDPR (performance of a contract to which the data subject is a party) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in providing a functioning and secure service).

3.2 Responding to requests via contact form

To manage correspondence with those who fill out a contact form, request information or documents. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures taken at the data subject's request).

3.3 Creation and management of the Personal Area

To allow registered users to access dedicated tools (self-help questionnaires, calculators, reserved content). Legal basis: Art. 6(1)(b) GDPR.

3.4 Transformation of the relationship from registered user to Firm Client

Should the registered user decide to formally grant a professional engagement to LX20, the data provided during registration may be supplemented and used for the management of the professional relationship. This evolution requires the signing of an engagement letter, submission of AML documentation, and acceptance of the specific regulations of Special Part A. Legal basis: Art. 6(1)(b) GDPR (performance of the professional mandate contract).

3.5 Informational communications and newsletters (only with explicit consent)

To send informational communications about the Firm's content (regulatory updates, published articles, events, market opinions) to users who have specifically given their consent. Legal basis: Art. 6(1)(a) GDPR (consent). Consent can be revoked at any time via a specific link in each communication or by accessing one's profile in the Personal Area. For detailed regulations, please refer to Special Part B.

3.6 Authentication via third-party OAuth providers (Google and similar)

To allow the user to access the Personal Area using Google credentials. In this case, LX20 receives from Google, with the user's prior consent at the time of authorization, the email address, display name, and Google profile identifier. LX20 does not have access to the Google password or other Google profile data that is not strictly necessary. Legal basis: Art. 6(1)(b) GDPR (performance of the contract requested by the data subject).

3.7 IT security and abuse prevention

To detect and counter unauthorized access attempts, service abuse, cyberattacks, and fraud. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller and third parties in the security of IT systems).

3.8 Anti-money laundering legal obligations (for Clients only)

To comply with the obligations of customer due diligence, document retention, and reporting of suspicious transactions pursuant to Legislative Decree 231/2007 and national and European anti-money laundering regulations. Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation).

3.9 Defense of a right in legal proceedings

To process personal data necessary for the establishment, exercise, or defense of a right in judicial or extrajudicial proceedings. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller) and Art. 9(2)(f) GDPR for any special categories of data.

3.10 Accounting, tax, and administrative compliance

To issue invoices, record transactions, and maintain accounting records. Legal basis: Art. 6(1)(c) GDPR.


4. Cookies and similar technologies

The use of technical, functionality, analytics, and profiling cookies is governed by the Cookie Policy available on the dedicated page, which is an integral part of this notice. For non-strictly necessary cookies, the user expresses or denies consent via the banner presented upon first access to the site. Preferences can be changed at any time via the "Manage cookie preferences" link at the bottom of each page.


5. Manner of processing and security measures

The processing of Personal Data is carried out in accordance with Art. 32 of the GDPR through automatic or manual means. Specifically, processing is carried out by means of: collection, recording, organization, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data.

Personal Data are subject to both paper-based and electronic and/or automated processing using methods and tools that comply with the security measures set forth in Art. 32 of the GDPR, by persons authorized to process Personal Data under the direct authority of the Controller. As mentioned, processing may also be delegated, through specific contracts, to external parties to LX20 appointed as data processors, who will act on documented instructions from LX20 itself, as the Data Controller.


6. Communication and dissemination of data

Personal data may be communicated to the following categories of subjects:

(a) The Firm's personnel and collaborators authorized to process data pursuant to Art. 29 GDPR, bound by professional confidentiality obligations and by specific written instructions.

(b) Technology service providers acting as Data Processors pursuant to Art. 28 GDPR, appointed through a specific contractual act.

(c) External professional consultants (accountant, labor consultant, auditor, any external DPO) acting as independent Data Controllers for their respective professional purposes or as Processors in the event of a specific delegation.

(d) Judicial, administrative, and supervisory authorities when communication is required by law, regulation, an order from a competent authority, or is necessary for legal defense.

(e) Banks and payment institutions limited to the data necessary for the management of financial flows (invoicing, collections, payments).

Personal data are not subject to dissemination (understood as communication to an indeterminate number of subjects).

The updated list of external Data Processors is available at the Firm upon written request to [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com).


7. Transfer of data outside the European Union

Personal Data are stored on servers located within the European Union. It is understood that the Data Controller, should it become necessary, will have the right to move the servers also to countries outside the European Union.

Any transfers to third countries shall take place exclusively on one of the bases provided for in Chapter V of the GDPR: (i) an adequacy decision by the European Commission (Art. 45 GDPR); (ii) in the absence of an adequacy decision, appropriate safeguards pursuant to Art. 46 GDPR, in particular standard contractual clauses adopted by the European Commission, accompanied where necessary by supplementary measures; (iii) residually and for individual operations, the derogations for specific situations provided for in Art. 49 GDPR. In any case, the Controller shall pre-emptively assess the level of protection ensured in the destination country and maintain documentary evidence of the safeguards adopted.


8. Data retention period

Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the principles of minimization and storage limitation (Art. 5(1)(c) and (e), GDPR). Specifically:

| Data type | Retention period | |---|---| | Navigation data (technical logs) | 12 months, unless required for the investigation of abuse | | Contact form data (without conversion into a Client) | 24 months from the last contact | | Personal Area registration data (non-Client user) | Until a deletion request is made or automatic deactivation after 24 months of continuous inactivity | | Firm's Client data | 10 years from the termination of the engagement (ordinary professional statute of limitations) — without prejudice to a longer term for specific obligations (AML: 10 years; tax and accounting obligations: 10 years from registration) | | AML due diligence data | 10 years from the date the transaction is carried out or from the termination of the relationship, pursuant to Art. 31 of D.Lgs. 231/2007 | | Consent to processing (logs) | For the duration of the purpose + 10 years for the purpose of proving that consent was obtained | | Newsletter (opt-in marketing) | Until consent is withdrawn, with active notification of termination to the user | | Data for legal defense | Until any ruling becomes final and unappealable or the legal action is extinguished |

At the end of the period, the data are deleted or irreversibly anonymized in such a way as to prevent the re-identification of the data subject.


9. Rights of the data subject

The data subject may exercise at any time the rights provided for in Articles 15 - 22 of the GDPR, and in particular:

(a) Right of access (Art. 15 GDPR): to obtain confirmation of the existence of processing and a copy of the data concerning them, together with information on the purpose, categories of data, recipients, retention period, and the origin of the data.

(b) Right to rectification (Art. 16 GDPR): to obtain the correction of inaccurate data or the completion of incomplete data.

(c) Right to erasure ("right to be forgotten", Art. 17 GDPR): to obtain the erasure of data when they are no longer necessary for the purposes for which they were collected, when the data subject withdraws consent (if consent is the legal basis), when the processing is unlawful, or when erasure is required by law. The right is subject to the limitations of Art. 17(3) of the GDPR (in particular, the Controller's legal obligations and the establishment, exercise or defence of legal claims).

(d) Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing when the data subject contests the accuracy of the data, when the processing is unlawful but the data subject opposes erasure, when the Controller no longer needs the data but the data subject requires them for the establishment, exercise or defence of legal claims, or pending the assessment of a possible objection.

(e) Right to data portability (Art. 20 GDPR): to receive the data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format and, where technically feasible, to have the data transmitted directly to another controller.

(f) Right to object (Art. 21 GDPR): to object at any time to the processing of data based on the Controller's legitimate interest, as well as to processing for direct marketing purposes (at any time and without needing to provide a reason).

(g) Right not to be subject to automated decision-making (Art. 22 GDPR): not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. LX20 does not currently use fully automated decision-making processes with such effects.

(h) Right to withdraw consent (Art. 7(3) GDPR): where processing is based on consent, the data subject may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

(i) Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): the data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, [protocollo@gpdp.it](mailto:protocollo@gpdp.it), as well as to bring proceedings before the competent judicial authority.

How to exercise rights

To exercise the rights listed above, the data subject may:

The Controller shall provide a response within one month of receiving the request, which may be extended up to a maximum of three months in cases of particular complexity (with a reasoned communication to the data subject within the first month). The exercise of rights is free of charge, except for manifestly unfounded or excessive requests (in particular because of their repetitive character), for which the Controller may charge a reasonable fee taking into account the administrative costs incurred.


10. Provision of data and consequences of refusal

The provision of data is optional, except for data necessary to provide the requested service. In particular:


11. Minors

The website and the Personal Area are not intended for individuals under the age of 18, and LX20 does not knowingly collect personal data from minors. Should it become known that a minor's data has been processed unintentionally, the Controller will delete it without undue delay. Parents or those with parental responsibility may report the presence of such data to the Controller at the address [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com).


12. Amendments to this policy

This policy may be updated at any time to adapt to regulatory, organisational, or technological changes. The most recent version is always available at the URL https://lx20lawfirm.com/en/privacy-policy. Substantial changes will be communicated to the user with reasonable prior notice via email to the registered address and by means of a prominent notice on the website. For users of the Personal Area, substantial changes may require a new explicit acceptance before the next login.


Special Part A — Client Portal

Regarding the processing of the Client's personal data within the scope of the services provided through the Client Area of the lx20lawfirm.com website

This Special Part supplements the General Part and specifically governs the processing carried out within the scope of the professional Client-Firm relationship through the Client Area. In the event of a conflict, the more specific and protective provisions for the data subject shall prevail.

A.1 Data processed within the Client Area

In addition to the data indicated in the General Part, LX20 processes the following categories of data in the Client Area relating to the Client, its legal representatives, and the individuals involved in the engagements:

A.1.1 Client's personal and identification data

First and last name (for natural persons), company name (for legal entities), tax identification number, VAT number, registered and operational office, data of the legal representative and directors, beneficial owner, and related anti-money laundering due diligence documentation.

A.1.2 Data relating to the assigned case

Internal case reference number, subject matter of the engagement, parties involved (Client, counterparties, judicial or administrative authorities, external consultants, experts), technical and legal documentation produced or received, correspondence exchanged, schedule of deadlines, activities performed and related timing, costs and invoicing.

A.1.3 Data relating to third parties

For the proper execution of the engagement, LX20 may process personal data of third parties (counterparties, witnesses, business counterparties, authorities, beneficial owners of transactions). Such individuals are informed of the processing pursuant to Art. 14 GDPR, subject to the limitation of Art. 14(5)(b), which exempts from the information obligation where this would involve a disproportionate effort, and without prejudice to the exercise of the data subject's rights. For data obtained from public databases (Chamber of Commerce, land registries, etc.), Articles 14 and 15 of the GDPR also apply.

A.1.4 Uploaded documents and files

Files of any kind uploaded by the Client to the Client Area through the upload or messaging functions, including contractual documents, judicial acts, documentary evidence, invoices, evidentiary documents, expert reports, certifications, and AML documentation.

A.1.5 Communication data

Messages exchanged between the Client and the Firm through the internal messaging feature, attachments to communications, read receipt logs, data relating to emails forwarded by the Firm to the Client (sender, recipient, subject, date, content).

A.1.6 Access and activity data

Logs of access to the Client Area, IP address, browser, device, authenticated sessions, activities performed (document downloads, messages sent, read receipts), security events (failed login attempts, password changes, activation of two-factor authentication).

A.1.7 Special categories of data

Should the specific case require it, LX20 may process special categories of data pursuant to Art. 9 GDPR (e.g., health data in a medical-legal dispute, data relating to criminal proceedings in a related case, data concerning ethnic origin or opinions in a labour dispute). In such cases:

A.2 Purposes of processing and legal basis

A.2.1 Performance of the professional mandate

Processing of data necessary for the provision of professional services as set out in the engagement letter (legal advice, drafting of documents, legal assistance in court, management of regulatory files, preparation of documents).

Legal basis: Art. 6(1)(b) GDPR (performance of the mandate agreement) and, for special categories of data, Art. 9(2)(f) GDPR.

A.2.2 Compliance with legal obligations

Compliance with the obligations imposed on the Firm by professional regulations and general law, in particular:

Legal basis: Art. 6(1)(c) GDPR.

A.2.3 Defence of a right

Processing of personal data of the Client or third parties necessary to establish, exercise, or defend a right in judicial, extrajudicial, or administrative proceedings, or for the protection of the Firm's rights.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and Art. 9(2)(f) GDPR for special categories.

A.2.4 Communication with the Client

Management of internal and external communications with the Client within the scope of the mandate, through the Client Area's messaging system, email, and telephone.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract).

A.2.5 Security and abuse prevention

Monitoring of access to the Client Area for security purposes, prevention of unauthorised access, detection of anomalies, and compliance audits.

Legal basis: Art. 6(1)(f) GDPR.

A.3 Professional legal privilege

Data processed within the Client-Firm relationship are covered by:

(a) Professional legal privilege pursuant to Art. 6 of Law no. 247/2012 and Art. 13 of the Codice Deontologico Forense (Code of Conduct for Lawyers). All employees, collaborators, and partners of the Firm are bound to respect this privilege.

(b) Professional secrecy under Art. 622 of the Italian Criminal Code, which criminally sanctions the disclosure of professional secrets by anyone who has become aware of a secret by reason of their status or office, profession, or art.

(c) Professional privilege enforceable against judicial authorities pursuant to Arts. 200 and 256 of the Italian Code of Criminal Procedure (c.p.p.) (with respect to documents and communications covered by privilege), within the limits provided by law.

Professional privilege applies in particular:

Any disclosure of data covered by privilege to third parties is made only:

A.4 Disclosure of data to third parties

In the performance of the mandate, LX20 may disclose personal data to:

(a) Staff and collaborators of the Firm authorised to process data (Art. 29 GDPR), bound by professional privilege and specific written instructions.

(b) External data processors appointed pursuant to Art. 28 GDPR:

(c) Judicial and administrative authorities:

(d) Parties involved in the mandate, within the limits necessary for the proper performance of the engagement:

(e) The Firm's insurance company for the management of any professional liability claims.

The updated list of external data processors is available upon the Client's written request.

A.5 Transfer of data outside the EU

For transfers of personal data outside the European Economic Area, please refer to the provisions of §7 of the General Part, including the provisions regarding the Controller's New York office. For transfers specifically concerning the Client-Firm relationship (e.g., international consultations, mandates with non-EU parties, storage of documents on systems managed in the United States), LX20 assesses the applicable safeguards on a case-by-case basis and adopts supplementary measures where necessary.

A.6 Data Retention Period

Data relating to the Client and to cases are retained in compliance with the following periods:

| Data Type | Retention Period | |---|---| | Documents relating to the engagement (deeds, contracts, legal opinions) | 10 years from the final closure of the engagement (ordinary professional limitation period pursuant to Art. 2946 of the Italian Civil Code) | | AML due diligence data (CDD/EDD) | 10 years from the termination of the relationship or the execution of the transaction (Art. 31 of Legislative Decree 231/2007) | | Accounting and tax documentation | 10 years from the date of recording (Art. 2220 of the Italian Civil Code and tax regulations) | | Client Area access logs | 24 months | | Messages in the internal messaging system | For the duration of the engagement + 10 years (as part of the engagement documentation) | | Technical backups | Retained on a maximum 12-month rotation |

Once these periods have elapsed, the data is deleted or irreversibly anonymised. Longer periods may apply only in the event of:

A.7 Rights of the data subject

The Client may exercise the rights provided for in Articles 15 - 22 of the GDPR (access, rectification, erasure, restriction, portability, objection, lodging a complaint with the Supervisory Authority) in accordance with the terms and procedures described in §9 of the General Part.

A.7.1 Specifics of the Client-Firm relationship

The exercise of privacy rights within the Client-Firm relationship is subject to certain specific limitations dictated by the professional nature of the relationship and applicable regulations:

A.7.2 Internal communications via the Client Area

The messaging functions of the Client Area are a tool for professional communication between the Client and the Firm, not a general channel for technical support or the exercise of privacy rights. To exercise privacy rights, the data subject must use the dedicated channels indicated in §9 of the General Part.

A.8 Specific security measures for the Client Portal

In addition to the general measures (§5 of the General Part), enhanced measures are adopted for the Client Area:

A.9 Provision of data and consequences of refusal

The provision of data requested for the performance of the engagement is mandatory for the purposes set out in §A.2.1 and §A.2.2. Refusal to provide such data makes it impossible to accept or continue the engagement. For AML obligations, refusal entails the Firm's mandatory abstention from performing the professional service pursuant to Articles 17 and 35 of Legislative Decree 231/2007.

A.10 Amendments to the notice

This Special Part is an integral part of the single information notice and follows the publication and update procedures set out in §12 of the General Part. Substantial amendments are communicated to the Client via email and/or a notice in the Client Area.

A.11 Contacts

For any request or to exercise rights relating to the processing of data within the Client Portal:

In case of a complaint, the Client may contact the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — [protocollo@gpdp.it](mailto:protocollo@gpdp.it)) or take legal action before the judicial authorities.


Special Part B — Newsletter

Pursuant to Articles 13 of Regulation (EU) 2016/679 (GDPR) and 130 of Legislative Decree 196/2003 (Privacy Code)

B.1 Data processed

For sending the LX20 newsletter, LX20 processes:

B.2 Purposes of processing and legal basis

The data is processed for the following purposes:

(a) Sending the periodic LX20 newsletter containing: regulatory and legislative updates, articles published by the Firm, notification of publications, invitations to professional events, and educational and informational content in the Firm's practice areas.

Legal basis: Art. 6(1)(a) GDPR (free, specific, informed, and unambiguous consent given upon subscription).

(b) Aggregated measurement of the newsletter's effectiveness (average open rate, average click rate, unsubscribe rate) for statistical and service improvement purposes.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller to measure the effectiveness of its communications in aggregate form).

(c) Technical management of subscriptions and unsubscriptions, compliance with GDPR transparency obligations.

Legal basis: Art. 6(1)(c) GDPR.

B.3 Newsletter characteristics

The newsletter does not contain third-party advertising, aggressive commercial offers, or products or services other than professional information.

B.4 Subscription and consent methods

Subscription to the newsletter is carried out through one of the following methods:

(a) Subscription form on the website with email confirmation ("double opt-in" procedure): the user enters their email address, receives a confirmation message with an activation link, and completes the subscription by clicking the link. This procedure ensures that consent has been knowingly given by the actual owner of the email address.

(b) Ticking the appropriate checkbox during registration for the Personal Area, separate and not pre-selected from the acceptance of the Terms and Conditions and the acknowledgment of this Policy: acceptance of the Terms is a condition for using the services, acknowledgment of the Policy does not constitute consent, and subscription to the newsletter is an optional and separate consent.

(c) Ticking the box during login via an OAuth provider (e.g., Google), managed on the consent completion page after the first login.

In all cases:

B.5 Withdrawal of consent and unsubscription

The user may withdraw their consent at any time, without needing to provide a reason and without any cost or prejudicial consequence.

Unsubscription methods:

(a) "Unsubscribe" link in every newsletter: present in the footer of every email sent. A single click automatically cancels the subscription, usually with immediate confirmation.

(b) From the user's profile page in the Personal Area: under "Communication Preferences," the user can untick the box for the newsletter. The change is effective immediately.

(c) Written request to the address [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com) with the subject "Newsletter Unsubscription". The Controller will process the request within 72 hours of receipt.

The withdrawal of consent leads to the immediate cessation of sending promotional communications. The data related to the subscription log (date, time, version of the policy accepted) are retained for the periods specified in §B.7 for the purpose of demonstrating historical consent, pursuant to Art. 7(1) GDPR.

The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

B.6 Communication and dissemination of data

The data is processed by:

(a) Firm personnel authorized to process data (Art. 29 GDPR).

(b) External data processors appointed pursuant to Art. 28 GDPR:

For other categories of Processors, please refer to §6 of the General Part.

The data is not disseminated or transferred to third parties for marketing purposes.

B.7 Data retention period

Data are retained for the following periods:

| Type | Retention | |---|---| | Subscribed email address + personal data | Until consent is withdrawn (unsubscription) | | Subscription log (date, time, policy version) | 10 years from the date of subscription, for the purpose of demonstrating consent pursuant to Art. 7(1) GDPR | | Unsubscription log | 10 years from the date of unsubscription, for the purpose of demonstrating the termination of processing | | Aggregated behavioural data (opens, clicks) | 24 months from the sending of the individual communication, in a form no longer associable with the data subject's identity |

Upon expiry of these periods, the data are deleted or irreversibly anonymised.

B.8 Data subject's rights

The data subject has the right, at any time, to:

To exercise these rights, the data subject may write to [info@lx20lawfirm.com](mailto:info@lx20lawfirm.com) or use the self-service features in the Personal Area (if registered).

B.9 Provision of data

The provision of the email address is necessary to provide the newsletter service. Any refusal will make it impossible to subscribe. The provision of first and last name is, however, optional.

B.10 Data transfers outside the EU

For data transfers outside the European Economic Area, please refer to §7 of the General Part. At the time of writing, newsletter data are processed exclusively by providers with servers located in the European Union (France for Brevo).

B.11 Changes to the policy

This Special Part is an integral part of the single policy and follows the publication and update methods set out in §12 of the General Part. The user will be informed of any substantial changes by email or by a notice on the dedicated page.

B.12 Contacts

For any request:


*Policy drafted in compliance with Reg. (EU) 2016/679 (GDPR), Legislative Decree 196/2003 as amended (Codice Privacy), Legislative Decree 231/2007 (AML), Law 247/2012 (ordinamento forense), and the Codice Deontologico Forense (Forensic Code of Conduct).*

LX20
Caricamento…